EU AI Act Fines and Penalties: The Three Tiers, the SME Cap, and the Risk That Bites First

The short answer: the EU AI Act sets three fine tiers — up to €35M or 7% of global annual turnover for prohibited practices, up to €15M or 3% for most other violations (high-risk duties, transparency, GPAI), and up to €7.5M or 1% for supplying incorrect information to authorities. For SMEs and startups, each cap applies at the lower of the fixed sum or percentage. Enforcement is live: penalty provisions have applied since August 2025, national market-surveillance authorities police the operator duties, and the Commission’s AI Office enforces GPAI rules from August 2026.

The three tiers, precisely

TierMaximumWhat triggers it
1€35,000,000 or 7% of worldwide annual turnover — whichever is higherProhibited practices (Article 5): social scoring, manipulative techniques, emotion inference at work/school, untargeted face scraping — and, from December 2, 2026, the new bans on AI-generated CSAM and non-consensual intimate content added by the Omnibus
2€15,000,000 or 3% — whichever is higherMost everything else: high-risk obligations, Article 50 transparency, deployer duties, GPAI obligations
3€7,500,000 or 1% — whichever is higherIncorrect, incomplete or misleading information to notified bodies or authorities

The startup-relevant nuance: for SMEs (including startups), each fine is capped at whichever of the two amounts is lower — the percentage, for almost any startup. The law also directs authorities to weigh proportionality, cooperation, and whether the violation was negligent or intentional. Translation: a documented, good-faith compliance effort is itself a fine-mitigation strategy.

Who enforces what, and since when

  • National market-surveillance authorities (one or more per member state) enforce operator obligations — prohibited practices, transparency, high-risk duties. Penalty regimes have applied since August 2, 2025; member states set their own procedural rules within the Act’s caps. (In practice, a number of member states were still completing their authority designations well into 2026 — part of why early enforcement is expected to concentrate on the most visible cases.)
  • The European Commission’s AI Office exclusively enforces GPAI-model obligations, with fining powers from August 2, 2026.
  • Timing follows the obligations themselves: you can’t be fined for high-risk non-compliance before the high-risk rules apply (December 2027 / August 2028 after the Omnibus) — but Article 5 bans, literacy, GPAI and, from August 2, 2026, Article 50 transparency are all enforceable reality.

One more lever that isn’t a fine: authorities can order corrective measures — up to withdrawal of a system from the EU market. For a startup, a withdrawal order in your biggest expansion market is worse than any realistic fine.

What enforcement will actually look like for startups

Honest assessment, since fear-marketing helps nobody:

  • You are not the first target. Early enforcement attention concentrates on prohibited practices, frontier models, and high-visibility deployments. A seed-stage SaaS with an unlabelled chatbot is unlikely to open the enforcement era.
  • But you’re exposed through your customers. EU enterprises push AI Act warranties into vendor contracts now. The first «penalty» most startups feel is a procurement questionnaire they can’t pass, a deal that stalls in legal review, or an indemnity clause they can’t sign. That cost arrives years before any regulator does.
  • Complaints are a vector. Like GDPR, expect competitor and user complaints to drive early cases. An unlabelled AI chatbot is visible to anyone who wants to report it.
  • The aggravating-factor pattern. GDPR practice shows authorities stacking «they also ignored X» into bigger cases. Cheap obligations left undone (AI literacy, disclosures) become multipliers in an otherwise survivable investigation.

How fines interact with GDPR (double exposure)

AI systems usually process personal data, so one incident can violate both regimes — and the fines are cumulative in principle: an unlawful emotion-recognition deployment could draw AI Act Tier 1 and GDPR Article 83 exposure (up to €20M/4%), plus, for non-EU companies, the missing-EU-representative aggravator. Compliance programs should treat AI Act + GDPR as one stack, not two projects.

Reducing exposure to near-zero, cheaply

For a transparency-tier startup, the full risk-retirement package is measured in weeks, not quarters:

  1. Kill Tier 1 risk (a day): audit the roadmap against Article 5 — the checklist step 2 covers it.
  2. Close Tier 2’s easy half (2–3 weeks): Article 50 disclosures and marking before August 2; documented AI literacy; vendor GPAI docs on file.
  3. Classify honestly (a week, with counsel if borderline): high-risk or not — and calendar 2027 if yes.
  4. Write it all down. Cooperation and demonstrable diligence are explicit mitigating factors. The memo you write this month is the discount on any future fine.

FAQ

What is the maximum fine under the EU AI Act?

€35 million or 7% of worldwide annual turnover, whichever is higher — for prohibited practices under Article 5.

What fine applies to transparency violations (Article 50)?

Up to €15 million or 3% of global turnover, whichever is higher — with the SME cap applying the lower amount for startups.

Are AI Act fines already enforceable in 2026?

Yes, for obligations already in force: prohibited practices, AI literacy, GPAI duties, and — from August 2, 2026 — Article 50 transparency. High-risk fines follow the high-risk deadlines in 2027–2028.

Do startups get lower fines?

The caps for SMEs apply at the lower of the fixed amount or percentage, and proportionality is a statutory factor — but «lower» is not «low»: 3% of turnover plus a stalled enterprise pipeline hurts at any stage.

Can regulators do anything besides fine us?

Yes — corrective orders up to withdrawal of the system from the EU market, which for most startups is the more expensive outcome.

Do AI Act and GDPR fines stack?

They can. One AI feature mishandling personal data can violate both regimes; the exposures are assessed separately.

Retire the risk in three weeks

Montaire & Co.’s Europe Risk Scan: your exposure across the AI Act and GDPR tiers, ranked by realistic cost — with the fix list. Fixed fee, one week.

30 minutes · senior advisor · no charge, no obligation

General information, not legal advice. Status as of July 16, 2026.